IOC Report
https://easy-rob.com/fileadmin/data/dwn/

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed May 22 14:19:25 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed May 22 14:19:25 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:54:41 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed May 22 14:19:25 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed May 22 14:19:25 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed May 22 14:19:25 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 100
PNG image data, 180 x 180, 8-bit/color RGBA, interlaced
dropped
Chrome Cache Entry: 101
ASCII text, with very long lines (383)
downloaded
Chrome Cache Entry: 102
JPEG image data, JFIF standard 1.00, resolution (DPI), density 96x96, segment length 16, comment: "LEAD Technologies Inc. V1.01", baseline, precision 8, 489x428, components 3
dropped
Chrome Cache Entry: 103
PNG image data, 250 x 250, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 104
PNG image data, 250 x 250, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 105
ASCII text, with very long lines (25245), with no line terminators
downloaded
Chrome Cache Entry: 106
ASCII text
downloaded
Chrome Cache Entry: 107
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 300x288, components 3
dropped
Chrome Cache Entry: 108
ASCII text, with very long lines (9959)
downloaded
Chrome Cache Entry: 109
Unicode text, UTF-8 text, with very long lines (22932)
downloaded
Chrome Cache Entry: 110
ASCII text
downloaded
Chrome Cache Entry: 111
ASCII text, with very long lines (9016)
downloaded
Chrome Cache Entry: 112
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 113
ASCII text, with very long lines (1443), with no line terminators
downloaded
Chrome Cache Entry: 114
PNG image data, 2000 x 2761, 8-bit/color RGB, interlaced
downloaded
Chrome Cache Entry: 115
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "CREATOR: gd-jpeg v1.0 (using IJG JPEG v80), quality = 82", baseline, precision 8, 250x168, components 3
downloaded
Chrome Cache Entry: 116
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 117
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 118
PNG image data, 250 x 250, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 119
PNG image data, 419 x 429, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 120
PNG image data, 2000 x 2761, 8-bit/color RGB, interlaced
dropped
Chrome Cache Entry: 121
ASCII text
downloaded
Chrome Cache Entry: 122
JPEG image data, JFIF standard 1.00, resolution (DPI), density 96x96, segment length 16, comment: "LEAD Technologies Inc. V1.01", baseline, precision 8, 515x497, components 3
downloaded
Chrome Cache Entry: 123
ASCII text
downloaded
Chrome Cache Entry: 124
JPEG image data, JFIF standard 1.00, resolution (DPI), density 96x96, segment length 16, comment: "LEAD Technologies Inc. V1.01", baseline, precision 8, 515x497, components 3
dropped
Chrome Cache Entry: 125
Unicode text, UTF-8 text, with very long lines (3013)
downloaded
Chrome Cache Entry: 126
Unicode text, UTF-8 text, with very long lines (1239)
downloaded
Chrome Cache Entry: 127
PNG image data, 180 x 180, 8-bit/color RGBA, interlaced
downloaded
Chrome Cache Entry: 128
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 129
PNG image data, 419 x 429, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 130
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "CREATOR: gd-jpeg v1.0 (using IJG JPEG v80), quality = 82", baseline, precision 8, 250x168, components 3
dropped
Chrome Cache Entry: 131
ASCII text, with very long lines (9071)
downloaded
Chrome Cache Entry: 132
HTML document, ASCII text, with very long lines (3794)
downloaded
Chrome Cache Entry: 133
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 300x288, components 3
downloaded
Chrome Cache Entry: 134
Unicode text, UTF-8 text, with very long lines (8443)
downloaded
Chrome Cache Entry: 135
ASCII text
downloaded
Chrome Cache Entry: 93
ASCII text, with very long lines (31997)
downloaded
Chrome Cache Entry: 94
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, comment: "LEAD Technologies Inc. V1.01", baseline, precision 8, 480x230, components 3
dropped
Chrome Cache Entry: 95
ASCII text
downloaded
Chrome Cache Entry: 96
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, comment: "LEAD Technologies Inc. V1.01", baseline, precision 8, 480x230, components 3
downloaded
Chrome Cache Entry: 97
JPEG image data, JFIF standard 1.00, resolution (DPI), density 96x96, segment length 16, comment: "LEAD Technologies Inc. V1.01", baseline, precision 8, 489x428, components 3
downloaded
Chrome Cache Entry: 98
ASCII text
downloaded
Chrome Cache Entry: 99
PNG image data, 250 x 250, 8-bit/color RGBA, non-interlaced
dropped
There are 40 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://easy-rob.com/fileadmin/data/dwn/
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2072 --field-trial-handle=1948,i,16417313546953028079,13420924789578503771,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8

URLs

Name
IP
Malicious
https://easy-rob.com/fileadmin/data/dwn/
https://easy-rob.com/wp-content/themes/easy-rob/assets/js/navigation.js?ver=20151215
149.126.6.57
https://easy-rob.com/wp-content/themes/easy-rob/style.css?ver=1583771668
149.126.6.57
http://jqueryvalidation.org/creditcard-method/
unknown
https://easy-rob.com/wp-includes/js/jquery/jquery.js?ver=1.12.4
149.126.6.57
https://easy-rob.com/wp-content/themes/easy-rob/assets/js/featherlight.gallery.min.js?ver=20151215
149.126.6.57
http://docs.jquery.com/Plugins/Validation/Methods/accept
unknown
https://easy-rob.com/wp-content/uploads/2019/01/er-collision-update-v7-3-250x250.png
149.126.6.57
https://easy-rob.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.4.1
149.126.6.57
http://stackoverflow.com/questions/3446170/escape-string-for-use-in-javascript-regex
unknown
https://easy-rob.com/wp-content/themes/easy-rob/assets/js/main.js?ver=20171215
149.126.6.57
https://developer.mozilla.org/en-US/docs/Web/API/CustomEvent/CustomEvent
unknown
https://git.io/vWdr2
unknown
https://easy-rob.com/wp-content/themes/easy-rob/assets/js/scripts.js
149.126.6.57
https://easy-rob.com/wp-content/themes/easy-rob/assets/img/easy-rob-logo.svg
149.126.6.57
http://www.gnu.org/licenses/gpl-2.0.html
unknown
http://www.noelboss.com)
unknown
https://easy-rob.com/
149.126.6.57
https://easy-rob.com/wp-includes/js/wp-embed.min.js?ver=5.1.18
149.126.6.57
https://easy-rob.com/fileadmin/data/dwn/
https://easy-rob.com/wp-content/uploads/2021/01/er-geo-assist.jpg
149.126.6.57
https://easy-rob.com/wp-content/themes/easy-rob/assets/js/readmore.js
149.126.6.57
http://noelboss.github.io/featherlight/
unknown
https://easy-rob.com/wp-content/plugins/login-sidebar-widget/js/jquery.validate.min.js?ver=5.1.18
149.126.6.57
https://easy-rob.com/wp-content/uploads/2019/03/ba1283cc0d.jpg
149.126.6.57
http://www.apache.org/licenses/LICENSE-2.0
unknown
https://easy-rob.com/wp-content/uploads/2018/08/er-wordpress-simulator-beispiel-2-seite4-250x168.jpg
149.126.6.57
https://easy-rob.com/favicon.ico
149.126.6.57
https://easy-rob.com/wp-content/themes/easy-rob/assets/js/equal-height.js?ver=20171215
149.126.6.57
https://easy-rob.com/wp-content/plugins/login-sidebar-widget/js/additional-methods.js?ver=5.1.18
149.126.6.57
https://easy-rob.com/wp-content/plugins/contact-form-7/includes/css/styles.css?ver=5.1.3
149.126.6.57
https://easy-rob.com/wp-content/uploads/2018/03/bildschirmfoto-2018-03-26-um-11-43-24-250x250.png
149.126.6.57
http://css-tricks.com/equal-height-blocks-in-rows/
unknown
http://davidwalsh.name/javascript-debounce-function
unknown
https://easy-rob.com/wp-content/themes/easy-rob/assets/img/favicon.png
149.126.6.57
https://easy-rob.com/wp-content/uploads/2018/04/david-jorre-477050-unsplash.png
149.126.6.57
http://felixf.de
unknown
https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw
142.250.185.196
http://jqueryvalidation.org/
unknown
https://easy-rob.com/fileadmin
149.126.6.57
https://easy-rob.com/wp-content/plugins/contact-form-7/includes/js/scripts.js?ver=5.1.3
149.126.6.57
http://www.easy-rob.com
unknown
https://easy-rob.com/wp-content/uploads/2019/03/35fa73a90a.jpg
149.126.6.57
https://easy-rob.com/fileadmin/data/
https://easy-rob.com/wp-content/uploads/2019/03/bildschirmfoto-2019-03-07-um-12-22-17-1.png
149.126.6.57
https://easy-rob.com/fileadmin/
https://easy-rob.com/wp-content/themes/easy-rob/assets/js/featherlight.min.js?ver=20151215
149.126.6.57
http://jedfoster.github.io/Readmore.js
unknown
https://easy-rob.com/fileadmin/data
149.126.6.57
https://easy-rob.com/wp-includes/js/wp-emoji-release.min.js?ver=5.1.18
149.126.6.57
https://easy-rob.com/wp-content/themes/easy-rob/assets/js/skip-link-focus-fix.js?ver=20151215
149.126.6.57
https://easy-rob.com/downloads/
http://developer.ean.com/general_info/Valid_Credit_Card_Types
unknown
https://easy-rob.com/wp-content/uploads/2021/01/autopath.jpg
149.126.6.57
https://easy-rob.com/wp-includes/css/dist/block-library/style.min.css?ver=5.1.18
149.126.6.57
https://easy-rob.com/wp-content/plugins/login-sidebar-widget/css/style_login_widget.css?ver=5.1.18
149.126.6.57
There are 45 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
easy-rob.com
149.126.6.57
www.google.com
142.250.185.196
s.w.org
192.0.77.48

IPs

IP
Domain
Country
Malicious
239.255.255.250
unknown
Reserved
142.250.185.196
www.google.com
United States
149.126.6.57
easy-rob.com
Switzerland
192.168.2.17
unknown
unknown
192.168.2.18
unknown
unknown

DOM / HTML

URL
Malicious
https://easy-rob.com/fileadmin/data/dwn/
https://easy-rob.com/fileadmin/data/
https://easy-rob.com/fileadmin/
https://easy-rob.com/downloads/